CLM & PKI AUTOMATION PLATFORM
Every certificate. One control plane.
ens0key discovers, inventories, and automates the lifecycle of every X.509 certificate in your organization — and runs the PKI behind it: your own issuing CA with CRL/OCSP, external CA connectors, and agents that deploy and renew certificates hands-free.
How it works
From finding a certificate to proving the renewal worked: six steps the platform runs on its own.
Discover
TLS scans of targets and CIDR ranges; agents reach the networks the server can't.
Inventory
Deduplicated by fingerprint, with observation history and ownership metadata.
Issue
Internal CA, ACME, DigiCert, EJBCA or ADCS — plus SCEP/EST for devices.
Deploy
Agents install into PEM, PKCS#12, JKS and IIS stores — agentless into appliances and cloud.
Renew
Zero-touch, on schedule, before expiry.
Verify
A service check proves the new certificate is serving — or the agent rolls back.
Verification with automatic rollback ships built in. Everyone else leaves that step to hand-written scripts.
What ens0key solves
Certificate outages, untracked keys, manual renewals: ens0key covers the full machine-identity lifecycle.
Certificate lifecycle
Know every certificate you have, where it lives, and when it expires — before it takes production down.
- ▸Network discovery of targets and CIDR ranges, plus agent-side discovery
- ▸Inventory deduplicated by SHA-256 fingerprint with observation history
- ▸Automatic flags: expired, expiring, self-signed, weak key, SHA-1
- ▸Expiry alerts via e-mail digests and Slack-compatible webhooks
PKI automation
Issue, renew, and revoke from one place — whether the CA is yours or someone else's.
- ▸Built-in issuing CA with a real CRL and OCSP responder
- ▸Connectors for ACME (RFC 8555), DigiCert CertCentral, and EJBCA
- ▸Encrypted key vault: AES-256-GCM envelope encryption, KMS/HSM-ready
- ▸Optional approval workflow before anything gets issued
Hands-free deployment
Agents put renewed certificates where they belong and reload the services that use them.
- ▸Pull-model agents over mTLS — no inbound connections, NAT-friendly
- ▸PEM, PKCS#12, and JKS certificate stores
- ▸Auto-renewal with reload hooks and service verification
- ▸Blueprints for mass rollout across your fleet
Built for your team
PKI & security teams
One inventory for public and internal certificates, your own issuing CA, issuance policies and approvals, with an audit trail your auditors can actually use.
See the features →Network & platform ops
Certificates on F5, Cisco ISE/ESA/WLC, FortiGate, NetScaler and cloud stores deployed without an agent; servers on auto-renewal with reload hooks and verification. No more 2 a.m. expiry calls.
See the platform →CISO & compliance
47-day certificate lifetimes are coming. Reports, RBAC, SIEM forwarding and an audit log you can hand straight to an auditor.
Why ens0key →Built for operators
Expiry heatmap, CA breakdown, key-strength report: inventory health at a glance, in designed dark and light themes.
Enterprise-grade from the first login
SSO & LDAP
OIDC sign-in with a Microsoft Entra ID preset, LDAPS, and a local break-glass admin.
RBAC
Viewer, operator, and admin roles mapped from SSO/LDAP groups — enforced server-side.
Audit log
Every mutation and every login attempt, recorded.
Backup & restore
Scheduled encrypted dumps to local, SFTP, SCP, or TFTP repositories; transactional in-app restore.
Plays well with what you already run
The documentation is public, from appliance import to daily operations. Read it before you register. Open the docs →
See ens0key on your own estate
A pilot takes one server and one PostgreSQL database. We'll help you scan your first ranges the same day.
Talk to us